Privacy Policy

Last updated: March 2025

1. Information We Collect

We collect your email address, trade data imported from connected exchanges (symbols, PnL, timestamps), profile information you provide (display name, bio), and usage data for analytics.

2. How We Use Your Information

We use your data to provide the trading journal service, calculate streaks and performance analytics, send notifications about badges and records, and improve the platform.

3. API Keys

Exchange API keys are encrypted using AES-256-GCM before storage. Encryption keys are stored separately from data. API keys are never logged, transmitted to third parties, or used for anything other than importing your trade history.

4. Data Sharing

We do not sell your data. We share data only with service providers necessary to run BitDiary (Supabase for database, Cloudflare R2 for storage). We may disclose data if required by law.

5. Public Profiles

If you enable your public profile, your display name, bio, and trading stats you choose to share become publicly accessible. You can disable this at any time in Settings.

6. Data Retention

We retain your data for as long as your account is active. You may request account deletion at any time, which will permanently delete all your data within 30 days.

7. Cookies

We use cookies for authentication sessions (Supabase Auth). We do not use tracking or advertising cookies.

8. Security

We implement industry-standard security measures including AES-256-GCM encryption, HTTPS, and Row Level Security on our database. However, no method of transmission over the internet is 100% secure.

9. Your Rights

You have the right to access, correct, or delete your personal data. Contact us to exercise these rights. EU residents have additional rights under GDPR.

10. Contact

For privacy questions, contact us at privacy@bitdiary.org